Executive brief
pretix is a ticketing and event management platform. A vulnerability in its PDF generation component allows attackers to inject HTML tags that force the server to download external images. This can be used to reveal internal server information or perform unauthorized requests within the organization's private network.
Technical details
The vulnerability is classified as SSRF through HTML injection (CWE-80). The PDF rendering engine in pretix fails to properly sanitize user-supplied content, allowing the inclusion of <img> tags. If an attacker provides a URL in the 'src' attribute, the rendering engine will attempt to fetch the image from that location. This can lead to the leakage of rendering server metadata or be used as a vector for SSRF against the local network. The issue is fixed in versions 2026.3.4, 2026.4.4, and 2026.5.2.
Affected products
- pretix pretix < 2026.3.4, 2026.4.0 to < 2026.4.4, 2026.5.0 to < 2026.5.2
Timeline
- 2026-06-25: disclosed
- 2026-06-25: patched: Released in versions 2026.3.4, 2026.4.4, and 2026.5.2
- 2026-06-25: advisory